Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13B51A468A2900DBDA483C774F298BF79246DC38BCB8B4298E2E8C03867C2D14DD116E4 |
|
CONTENT
ssdeep
|
48:THy9hKRup1ZcY/E+hYK8bKoDXPp4ODENcf/x1HSENcf/GrCgQ/H:TS9wErYNOqXPp4ODlMaHQ/H |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ddb273c88c6299a6 |
|
VISUAL
aHash
|
fffffef8f8f8e0c0 |
|
VISUAL
dHash
|
020c3030b0b00800 |
|
VISUAL
wHash
|
376edcf878f8c080 |
|
VISUAL
colorHash
|
380030000c0 |
|
VISUAL
cropResistant
|
020c3030b0b00800 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.